US10936740B2

Systems and methods for securing an entity-relationship system

Summary by NHIP

Entity-Relationship Database Security

The method secures data in an entity-relationship database by storing access rules within the system model. It permits entity creation only after a "create-check" process grants permission while using a separate "non-create-check" process for reading, modifying, or deleting entities, with rules including a filter defining a subset of entities.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A computer implemented method of securing information stored in an entity relationship database system comprising at least one entity relationship database, the information stored in the entity relationship database system being stored according to an entity relationship model, the method comprising the steps of: specifying access rules limiting access to the entity relationship database system; storing the access rules in the entity relationship database system according to the entity relationship model; permitting an accessor to create an entity in the entity relationship database system if a “create-check” process dependent upon at least one of the one or more stored access rules grants permission; and permitting the accessor to read or modify or delete an entity stored in the entity relationship database system if a “non-create-check” process dependent upon at least one of the one or more stored access rules grants permission.

US10936740B2, drawing sheet 1
Sheet 1 of 22

Term

11.2 yearsleft in the term

Expires 5 December 2037, including 307 days of term adjustment.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

16 claims: 3 independent, 13 dependent

  1. 1
    Broadest claimClaim Score 36, narrow(NHIP)A computer implemented method of securing information stored in an entity-relationship database system comprising at least one entity-relationship database, the information stored in the entity-relationship database system being stored according to an entity-relationship model, the method comprising the steps of:specifying one or more access rules limiting access to the entity relationship entity-relationship database system;storing the one or more access rules in the entity-relationship entity relationship database system according to the entity-relationship entity relationship model;permitting an accessor to create an entity in the entity-relationship database system if a “create-check” process dependent upon at least one of the one or more stored access rules grants permission;and denying the accessor permission to create the entity in the entity-relationship database system if the “create-check” process does not grant permission;permitting the accessor to read or modify or delete an entity stored in the entity-relationship database system if a “non-create-check” process dependent upon at least one of the one or more stored access rules grants permission;and denying the accessor permission to read or modify or delete an entity stored in the entity-relationship database system if the “non-create” check process does not grant permission;wherein the one or more access rules further comprise a filter defining a subset of entities of the specified type of entity for which the one or more access rules can grant permission.
  2. 14
    A system for securing information stored in an entity-relationship entity relationship database system comprising at least one entity-relationship entity relationship database, the information stored in the entity-relationship entity relationship database system being stored according to an entity-relationship entity relationship model, the system comprising:one or more processors for executing respective software programs stored in respective memory devices in order to perform a method comprising the steps of:specifying one or more access rules limiting access to the entity-relationship entity relationship database system;storing the one or more access rules in the entity-relationship entity relationship database system according to the entity-relationship entity relationship model;permitting an accessor to create an entity in the entity-relationship database system if a “create-check” process dependent upon at least one of the one or more stored access rules grants permission;and denying the accessor permission to create the entity in the entity-relationship database system if the “create-check” process does not grant permission;permitting the accessor to read or modify or delete an entity stored in the entity-relationship database system if a “non-create-check” process dependent upon at least one of the one or more stored access rules grants permission;and denying the accessor permission to read or modify or delete an entity stored in the entity-relationship database system if the “non-create” check process does not grant permission;wherein the one or more access rules further comprise a filter defining a subset of entities of the specified type of entity for which the one or more access rules can grant permission.
  3. 15
    One or more computer readable non-transitory tangible storage media storing respective software programs for directing respective processors to secure information stored in an entity-relationship entity relationship database system comprising at least one entity-relationship entity relationship database, the information stored in the entity-relationship entity relationship database system being stored according to an entity-relationship entity relationship model, the software programs comprising:computer executable code for specifying one or more access rules limiting access to the entity-relationship entity relationship database system;computer executable code for storing the one or more access rules in the entity-relationship entity relationship database system according to the entity-relationship entity relationship model;computer executable code for permitting an accessor to create an entity in the entity-relationship database system if a “create-check” process dependent upon at least one of the one or more stored access rules grants permission;and for denying the accessor permission to create the entity in the entity-relationship database system if the “create-check” process does not grant permission;computer executable code for permitting the accessor to read or modify or delete an entity stored in the entity-relationship database system if a “non-create-check” process dependent upon at least one of the one or more stored access rules grants permission;and for denying the accessor permission to read or modify or delete an entity stored in the entity-relationship database system if the “non-create” check process does not grant permission;wherein the one or more access rules further comprise a filter defining a subset of entities of the specified type of entity for which the one or more access rules can grant permission.